Apache Http Server vulnerabilities
299 known vulnerabilities affecting apache/http_server.
Total CVEs
299
CISA KEV
5
actively exploited
Public exploits
66
Exploited in wild
7
Severity breakdown
CRITICAL33HIGH95MEDIUM158LOW13
Vulnerabilities
Page 12 of 15
CVE-2004-0748MEDIUMCVSS 5.0≥ 2.0.35, < 2.0.512004-10-20
CVE-2004-0748 [MEDIUM] CWE-835 CVE-2004-0748: mod_ssl in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (CPU consu
mod_ssl in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (CPU consumption) by aborting an SSL connection in a way that causes an Apache child process to enter an infinite loop.
nvd
CVE-2004-0786MEDIUMCVSS 5.0≥ 2.0.35, < 2.0.512004-10-20
CVE-2004-0786 [MEDIUM] CVE-2004-0786: The IPv6 URI parsing routines in the apr-util library for Apache 2.0.50 and earlier allow remote att
The IPv6 URI parsing routines in the apr-util library for Apache 2.0.50 and earlier allow remote attackers to cause a denial of service (child process crash) via a certain URI, as demonstrated using the Codenomicon HTTP Test Tool.
nvd
CVE-2004-0751MEDIUMCVSS 5.0PoC≥ 2.0.44, < 2.0.512004-10-20
CVE-2004-0751 [MEDIUM] CVE-2004-0751: The char_buffer_read function in the mod_ssl module for Apache 2.x, when using reverse proxying to a
The char_buffer_read function in the mod_ssl module for Apache 2.x, when using reverse proxying to an SSL server, allows remote attackers to cause a denial of service (segmentation fault).
nvd
CVE-2004-0809MEDIUMCVSS 5.0≥ 2.0.35, < 2.0.512004-09-16
CVE-2004-0809 [MEDIUM] CVE-2004-0809: The mod_dav module in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service
The mod_dav module in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (child process crash) via a certain sequence of LOCK requests for a location that allows WebDAV authoring access.
nvd
CVE-2004-0492CRITICALCVSS 10.0v1.3.26v1.3.27+3 more2004-08-06
CVE-2004-0492 [CRITICAL] CVE-2004-0492: Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote at
Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negative Content-Length HTTP header field, which causes a large amount of data to be copied.
nvd
CVE-2004-0493MEDIUMCVSS 6.4PoCv2.0.47v2.0.48+1 more2004-08-06
CVE-2004-0493 [MEDIUM] CVE-2004-0493: The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a deni
The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memory exhaustion), and possibly an integer signedness error leading to a heap-based buffer overflow on 64 bit systems, via long header lines with large numbers of space or tab characters.
nvd
CVE-2004-0488HIGHCVSS 7.5≥ 2.0.35, < 2.0.502004-07-07
CVE-2004-0488 [HIGH] CWE-787 CVE-2004-0488: Stack-based buffer overflow in the ssl_util_uuencode_binary function in ssl_util.c for Apache mod_ss
Stack-based buffer overflow in the ssl_util_uuencode_binary function in ssl_util.c for Apache mod_ssl, when mod_ssl is configured to trust the issuing CA, may allow remote attackers to execute arbitrary code via a client certificate with a long subject DN.
nvd
CVE-2004-0174HIGHCVSS 7.5≤ 2.0.492004-05-04
CVE-2004-0174 [HIGH] CWE-667 CVE-2004-0174: Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certai
Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to cause a denial of service (blocked new connections) via a "short-lived connection on a rarely-accessed listening socket."
nvd
CVE-2004-0173MEDIUMCVSS 5.0PoCv0.8.11v0.8.14+9 more2004-04-15
CVE-2004-0173 [MEDIUM] CVE-2004-0173: Directory traversal vulnerability in Apache 1.3.29 and earlier, and Apache 2.0.48 and earlier, when
Directory traversal vulnerability in Apache 1.3.29 and earlier, and Apache 2.0.48 and earlier, when running on Cygwin, allows remote attackers to read arbitrary files via a URL containing "..%5C" (dot dot encoded backslash) sequences.
nvd
CVE-2003-0993HIGHCVSS 7.5v1.3v1.3.1+20 more2004-03-29
CVE-2003-0993 [HIGH] CVE-2003-0993: mod_access in Apache 1.3 before 1.3.30, when running big-endian 64-bit platforms, does not properly
mod_access in Apache 1.3 before 1.3.30, when running big-endian 64-bit platforms, does not properly parse Allow/Deny rules using IP addresses without a netmask, which could allow remote attackers to bypass intended access restrictions.
nvd
CVE-2004-0113MEDIUMCVSS 5.0v2.0.35v2.0.36+12 more2004-03-29
CVE-2004-0113 [MEDIUM] CVE-2004-0113: Memory leak in ssl_engine_io.c for mod_ssl in Apache 2 before 2.0.49 allows remote attackers to caus
Memory leak in ssl_engine_io.c for mod_ssl in Apache 2 before 2.0.49 allows remote attackers to cause a denial of service (memory consumption) via plain HTTP requests to the SSL port of an SSL-enabled server.
nvd
CVE-2004-1834LOWCVSS 2.1v2.0v2.0.9+17 more2004-03-20
CVE-2004-1834 [LOW] CVE-2004-1834: mod_disk_cache in Apache 2.0 through 2.0.49 stores client headers, including authentication informat
mod_disk_cache in Apache 2.0 through 2.0.49 stores client headers, including authentication information, on the hard disk, which could allow local users to gain sensitive information.
nvd
CVE-2003-0987HIGHCVSS 7.5≤ 1.3.302004-03-03
CVE-2003-0987 [HIGH] CVE-2003-0987: mod_digest for Apache before 1.3.31 does not properly verify the nonce of a client response by using
mod_digest for Apache before 1.3.31 does not properly verify the nonce of a client response by using a AuthNonce secret.
nvd
CVE-2004-1082HIGHCVSS 7.5v1.3v1.3.1+20 more2004-02-03
CVE-2004-1082 [HIGH] CVE-2004-1082: mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce
mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attackers to replay credentials.
nvd
CVE-2003-1307MEDIUMCVSS 4.3PoCv2.0v2.0.9+17 more2003-12-31
CVE-2003-1307 [MEDIUM] CVE-2003-1307: The mod_php module for the Apache HTTP Server allows local users with write access to PHP scripts to
The mod_php module for the Apache HTTP Server allows local users with write access to PHP scripts to send signals to the server's process group and use the server's file descriptors, as demonstrated by sending a STOP signal, then intercepting incoming connections on the server's TCP port. NOTE: the PHP developer has disputed this vulnerability, saying "The op
nvd
CVE-2003-1418MEDIUMCVSS 4.3v1.3.22v1.3.23+4 more2003-12-31
CVE-2003-1418 [MEDIUM] CWE-200 CVE-2003-1418: Apache HTTP Server 1.3.22 through 1.3.27 on OpenBSD allows remote attackers to obtain sensitive info
Apache HTTP Server 1.3.22 through 1.3.27 on OpenBSD allows remote attackers to obtain sensitive information via (1) the ETag header, which reveals the inode number, or (2) multipart MIME boundary, which reveals child process IDs (PID).
nvd
CVE-2003-0789CRITICALCVSS 10.0≥ 2.0.35, < 2.0.482003-11-03
CVE-2003-0789 [CRITICAL] CVE-2003-0789: mod_cgid in Apache before 2.0.48, when using a threaded MPM, does not properly handle CGI redirect p
mod_cgid in Apache before 2.0.48, when using a threaded MPM, does not properly handle CGI redirect paths, which could cause Apache to send the output of a CGI program to the wrong client.
nvd
CVE-2003-0542HIGHCVSS 7.2v1.3v1.3.1+34 more2003-11-03
CVE-2003-0542 [HIGH] CWE-119 CVE-2003-0542: Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29
Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9 captures.
nvd
CVE-2003-0460MEDIUMCVSS 5.0≤ 1.3.272003-08-27
CVE-2003-0460 [MEDIUM] CVE-2003-0460: The rotatelogs program on Apache before 1.3.28, for Windows and OS/2 systems, does not properly igno
The rotatelogs program on Apache before 1.3.28, for Windows and OS/2 systems, does not properly ignore certain control characters that are received over the pipe, which could allow remote attackers to cause a denial of service.
nvd
CVE-2003-0192MEDIUMCVSS 6.4v2.0v2.0.28+13 more2003-08-18
CVE-2003-0192 [MEDIUM] CVE-2003-0192: Apache 2 before 2.0.47, and certain versions of mod_ssl for Apache 1.3, do not properly handle "cert
Apache 2 before 2.0.47, and certain versions of mod_ssl for Apache 1.3, do not properly handle "certain sequences of per-directory renegotiations and the SSLCipherSuite directive being used to upgrade from a weak ciphersuite to a strong one," which could cause Apache to use the weak ciphersuite.
nvd